HID has announced the integration of Enterprise Attestation in its suite of FIDO standard-based authenticators, including smart cards and keys.
This capability enables organizations to ensure that only company-issued passkeys are used during registration, verifying the origin of the authenticators prior to credential acceptance. By implementing this, organizations can enhance device trust, gain insights into the source of authenticators, and maintain high-assurance authentication without increasing complexity for users.
User Login Experience
While passkeys effectively tackle phishing threats, enterprises need assurance that the devices generating these credentials are trustworthy and issued by them. According to the FIDO Alliance report on Passkey Deployment in Enterprises, regulatory compliance is a barrier for 20% of organizations adopting passkeys. Enterprise Attestation provides a solution by making device trust and governance explicit and enforceable.
Enterprise Attestation provides a solution by making device trust and governance explicit
Without it, an enterprise might unwittingly register personal authenticators instead of those they distribute and control. This feature verifies the device's issuance by the organization, supplying security teams with necessary governance and traceability without altering user login experiences.
Valid Attestation Data
Embedded into HID’s Crescendo series, which includes FIDO2-certified smart cards and security keys, and compatible with platforms like PingOne, Enterprise Attestation confirms authenticator provenance at passkey registration.
If a device fails to present valid attestation data, enrollment is blocked, adhering to policies without necessitating changes in application workflows or user steps. As part of the FIDO Alliance’s WebAuthn and CTAP specifications, this approach supports standard passkey governance, avoiding proprietary systems or deviations in user experience.
Healthcare and Critical Infrastructure
While this filters unauthorized hardware, it cannot confirm the device's issuance source
Highly regulated sectors such as financial services, healthcare, and critical infrastructure benefit significantly from Enterprise Attestation. This capability assists in compliance with auditing, device provenance, and lifecycle management requirements. Global firms guided by frameworks like the EU's NIS2 Directive, DORA, and Zero Trust principles can utilize this feature to enforce policy at the authenticator level effectively.
To illustrate the practical application of Enterprise Attestation, consider a global retailer restricting passkey registration to specified authenticator models. While this filters unauthorized hardware, it cannot confirm the device's issuance source.
Enterprise Attestation resolves this by checking for a certificate linking the device to a recognized, company-issued authenticator. Enrollment is blocked if the certificate is absent or unrecognized. If access is granted, the user's login experience remains unchanged, while the organization gains a verifiable and auditable record of each device's registration. HID’s Crescendo authenticators with Enterprise Attestation are now available worldwide.
HID, a global pioneer in trusted identity solutions, announces the availability of Enterprise Attestation in its FIDO authenticator portfolio of smart cards and keys, a FIDO standards-based capability that enables organizations to enforce only company-issued passkeys at registration, proving authenticator provenance before a credential is ever accepted.
By doing so, Enterprise Attestation helps organizations strengthen device trust, gain visibility into authenticator origin and support high-assurance authentication without adding friction for users.
User login experience
While passkeys address phishing, enterprises also need assurance that the devices creating those credentials are ones they have issued and trust. In the FIDO Alliance’s State of Passkey Deployment in the Enterprise report, 20% of organizations cite strict regulations as a key barrier to passkey adoption.
Enterprise Attestation addresses this gap by making device trust and authenticator governance explicit and enforceable. Without it, a personal authenticator could be registered to an employee, with no reliable way for the enterprise to distinguish it from a credential enrolled on a device the organization controls, monitors and can revoke. Enterprise Attestation verifies that the device being registered was issued by the organization. It gives security teams the governance, traceability and device control they need without changing the user login experience.
Valid attestation data
Built into HID’s Crescendo authenticators, including FIDO2-certified smart cards and security keys, and supported by identity platforms such as PingOne, Enterprise Attestation verifies authenticator provenance at the point of passkey registration. If a device cannot present valid attestation data, enrollment is blocked by policy, without requiring any changes to application workflows or additional steps for users.
Enterprise Attestation is part of the FIDO Alliance’s WebAuthn and Client to Authenticator Protocol (CTAP) specifications and is actively supported through the FIDO Alliance Enterprise Deployment Working Group. This standards-based foundation ensures organizations can enforce passkey governance without proprietary authentication flows, application lock-in or deviations from the standard user experience.
Healthcare and critical infrastructure
For highly regulated industries such as financial services, healthcare and critical infrastructure, the capability directly supports compliance requirements around auditability, device provenance and lifecycle control.
Global organizations operating under frameworks such as the European Union's NIS2 Directive, the Digital Operational Resilience Act (DORA, applicable to EU financial services organizations) and Zero Trust mandates gain a practical mechanism to enforce policy at the authenticator level.
Approved authenticator models
To understand what Enterprise Attestation adds in practice, consider a global retailer that currently restricts passkey registration to approved authenticator models. This approach filters unauthorized hardware, but it cannot confirm whether a specific device was actually issued by the company or sourced independently by an employee.
Enterprise Attestation solves that problem. When a device attempts to enroll, the system checks for a certificate that ties it to a known, company-issued authenticator. If that certificate is absent or unrecognised, enrollment is blocked. If granted access, the end user sees no change to their login experience, but the organization gains a verifiable, auditable record of every device that has been granted access at registration. HID Crescendo authenticators with Enterprise Attestation support are available globally now.